Hacker News new | ask | show | jobs
by ibdf 2979 days ago
Why is something like "alksjdlq" or "alskjdlakjv" weak? Do brutal force attacks focus on any combination of characters? or combination of known words?

If the password above is not a word, or a combination of words, or something personal, and it's long enough... how is it not a strong password?

Also, if you five away what a strong password consists of (case, length, characters, symbols) then doesn't that make it weaker because you give bots/attackers a pattern to follow?

1 comments

> Also, if you five away what a strong password consists of (case, length, characters, symbols) then doesn't that make it weaker because you give bots/attackers a pattern to follow?

I don't think it changes anything at all. Attackers won't ignore "dolphins" just because a meter says it's weak.

Unless it's an actual limitation of the site where you're signing up, in which case the culprit for the reduced search space would be the website for such password limitations, not because the password strength meter.